Per Prisma Cloud community guidance: paste the service-account JSON (not a token) and apply the permissions template, or scans fail with 403.

Context: Problem: Setting up GCP agentless scanning in the Prisma Cloud Compute console. Paste the full contents of the service account JSON key file into the service account field, and leave the API token field empty. When the scan runs, "failed to create account clients ... Error 403: Required compute.zones.list permission" means the downloaded permissions template was never applied to the service account - apply it in GCP IAM, then retry the scan.